Threat Library

Agent-to-agent threats first — conventional coverage one click away.

Browse by hub: AI agent threats · Conventional watchlist · OWASP Agentic Top 10

Showing 20 of 1541 threats

MCPwebsocketorigin-validationCSWSHcross-site-websocket-hijackingmcp-python-sdkdeprecated-transportASI05 · Unsafe Code ExecutionSurface: ProtocolPropagation: Single Hop

The deprecated WebSocket transport in the MCP Python SDK accepted connections without validating Host or Origin headers, meaning any malicious webpage a victim's browser visits could open a WebSocket connection to a locally or network-exposed MCP server. This is a classic Cross-Site WebSocket Hijacking (CSWSH) pattern that could let an attacker-controlled origin interact with an MCP server's tools on behalf of an unwitting user. Severity is moderated because the affected transport is deprecated and impact depends on what the exposed server can do and whether it's reachable from a browser context.

mcpbroken-access-controlsession-isolationidortask-managementpython-sdkmulti-tenantASI06 · Memory PoisoningSurface: ProtocolPropagation: Single Hop

The MCP Python SDK's experimental task management feature failed to bind tasks to the session that created them, allowing any connected client to list, read, cancel, or consume messages for tasks belonging to other clients. This is a broken access control / IDOR-style flaw that breaks the trust boundary between concurrent MCP sessions on the same server. It is fixed in version 1.27.2.

MCPsession-hijackingauthentication-bypassSSEstreamable-httpJSON-RPCbroken-authorizationASI06 · Memory PoisoningSurface: ProtocolPropagation: Single Hop

The MCP Python SDK's SSE and stateful Streamable HTTP transports route messages to sessions based solely on a session ID, without checking that the requesting client is the same authenticated principal who created that session. Any bearer-token-authenticated client that learns or guesses a valid session ID can inject JSON-RPC messages into another user's active session, effectively hijacking it. This is a serious cross-tenant authorization flaw fixed in version 1.27.2.

prompt-injectiondata-exfiltrationlethal-trifectaclaudeweb_fetchanthropictool-misusememory-poisoningASI05 · Unsafe Code ExecutionAML.T0051AML.T0043Surface: Tool LayerPropagation: Single Hop

A researcher discovered a loophole in Anthropic's Claude web_fetch tool that allowed a malicious website to exfiltrate private user data (name, location, employer) by chaining together a sequence of attacker-controlled links discovered within previously fetched pages. This bypassed the intended safeguard that web_fetch could only follow user- or search-originated URLs, effectively encoding stolen data letter-by-letter into a series of outbound requests. Anthropic has since patched the issue by disallowing navigation to links found within fetched content.

MCPRCEunauthenticatedplugin-bridgenetwork-exposedpenpotASI05 · Unsafe Code ExecutionSurface: Tool LayerPropagation: Single Hop

Penpot's MCP server component exposed an unauthenticated HTTP endpoint bound to all network interfaces that allowed arbitrary JavaScript execution on the host. Any network-adjacent attacker could remotely execute code without credentials, making this a critical, easily exploitable vulnerability in an agent-tooling component.

cursorcloud-agentssrfunauthenticated-endpointcredential-theftbrowser-agentsandbox-escapegithub-token-leakASI05 · Unsafe Code ExecutionAML.T0051AML.T0048Surface: Tool LayerPropagation: Single Hop

Cursor's browser-enabled Cloud Agent exposed a local agent control endpoint without authentication, allowing malicious web content encountered by the agent's browsing capability to reach it from inside the sandbox. This let attacker-controlled pages trigger code execution within the agent's session and steal repository files, environment variables, credentials, and GitHub App tokens. The vendor fixed the issue by requiring authentication on the endpoint.

defensive-researchprompt-injection-detectionhidden-state-analysisactivation-probingpurpose-specific-agentstraining-free-defensenot-an-exploitASI01 · Goal HijackingAML.T0051Surface: ModelPropagation: None

This is a defensive research paper, not a disclosed vulnerability or active exploit. It proposes PVDetector, a training-free method to detect prompt injection attacks against purpose-specific LLM agents by analyzing hidden activation states for 'policy-violation' concepts rather than just input/output text. Since the raw data describes a detection technique intended to help defenders, it does not itself constitute a threat.

MCPunauthenticated-accesstool-calldefault-configmissing-authinput-validationpraisonaiASI06 · Memory PoisoningSurface: ProtocolPropagation: Single Hop

PraisonAI versions before 4.6.78 default to running the MCP HTTP-stream server without any API key or authentication, meaning anyone who can reach the endpoint can list and invoke all exposed tools. The server also fails to validate tool-call arguments against the advertised schema, compounding the risk of malformed or malicious inputs reaching tool handlers. Exploitation requires the operator to have bound the server to a network-accessible address rather than the safe localhost default.

MCPSSRFconfused-deputycredential-exfiltrationcloud-metadataunauthenticatedGrafanaASI04 · Agentic Supply ChainSurface: Tool LayerPropagation: Single Hop

An unauthenticated attacker can abuse the Grafana MCP Server by injecting a crafted X-Grafana-URL header, tricking the server into acting as a proxy that leaks its own privileged Grafana service-account token. This same flaw allows server-side request forgery against internal networks and cloud metadata endpoints, giving attackers a path to full credential theft and internal reconnaissance without needing any prior authentication.

agent-relevantbrowser-extensionai-agentclaude-for-chromeanthropicprivilege-escalationdata-exposurerogue-extension

Security researchers found that Claude for Chrome, Anthropic's browser-based AI agent, can be manipulated by any other malicious browser extension capable of injecting a script into claude.ai. This allows a rogue extension to trigger Claude's authenticated agent actions, silently reading a victim's Gmail, Google Docs (including comments), and Calendar without direct user consent for that specific action. The flaw is related to but distinct from the previously disclosed 'ClaudeBleed' issue, sharing the same rogue-extension prerequisite but differing in the scope of accessible data.

SAPNetWeaverABAPmemory-corruptionout-of-bounds-writeenterprise-softwarepatch-tuesday

SAP has patched a critical out-of-bounds write vulnerability (CVE-2026-44747, CVSS 9.9) in NetWeaver Application Server ABAP that allows an authenticated attacker to trigger memory corruption, potentially exposing or modifying sensitive business data. The flaw was addressed as part of SAP's July 2026 security update cycle alongside other vulnerabilities.

microsoftpatch-tuesdayzero-dayactive-exploitationwindowsvulnerability-managementagent-relevant

Microsoft's July 2026 Patch Tuesday addressed 622 CVEs, its largest release on record and more than triple the prior high, including two zero-day vulnerabilities confirmed to be under active exploitation. The advisory was informed by incident responders, indicating real-world attack activity preceded the patches. Organizations should prioritize immediate patching given the scale of the release and confirmed in-the-wild abuse.

githubinfostealermalwaresupply-chaintyposquattingsoftware-impersonationagent-relevant

A threat actor has created nearly 300 fake GitHub repositories impersonating legitimate software and security tools to distribute infostealer malware. Developers and security researchers searching for these tools risk downloading and executing malicious code disguised as trusted projects.

BECbusiness-email-compromiseinvestment-fraudmoney-launderinglaw-enforcement-actionfinancial-crime

Spanish National Police dismantled a cybercrime and money-laundering network responsible for approximately €140 million ($160 million) in losses through investment fraud and business email compromise (BEC) schemes. Four suspects were arrested in connection with the operation, which targeted victims through social engineering and fraudulent financial transactions.

SonicWallSMA1000zero-dayVPNremote-accessedge-deviceexploited-in-the-wild

SonicWall has disclosed that two vulnerabilities in its SMA1000 Secure Mobile Access appliances are being actively exploited as zero-days. The company has released security updates and is urging all customers to patch immediately to prevent further compromise.

ICSSCADADLL-hijackinglocal-privilege-escalationABBCWE-427critical-infrastructure

ABB disclosed CVE-2025-13162, an uncontrolled search path (DLL hijacking) vulnerability affecting Online Builder (ONB) as included in Control Builder A and 800xA for Advant Master. A local attacker with prior system access could place a malicious DLL in an unrestricted application directory to achieve arbitrary code execution on the affected node.

ICSOTprivilege-escalationlinux-kernelABBcritical-infrastructureCWE-669

A high-severity local privilege escalation vulnerability (CVE-2026-31431, 'Copy Fail') affects ABB Ability Edgenius edge computing platforms due to a flaw in the Linux kernel's algif_aead cryptographic interface. A locally authenticated user or compromised container workload could exploit incorrect in-place memory operations to gain full root access on affected devices. ABB has released version 3.2.4.1 to remediate the issue.

CISAKEVSonicWallSSRFcode-injectionMicrosoftActive-DirectorySharePointfederalBOD-26-04agent-relevant

CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities Catalog, affecting SonicWall SMA1000 appliances (SSRF and code injection) and Microsoft Active Directory Federation Services and SharePoint Server (access control and authentication bypass issues). These flaws are being actively exploited in the wild and pose significant risk to federal and enterprise networks, with BOD 26-04 mandating rapid remediation for FCEB agencies.

apache-kylinos-command-injectionrcecve-2026-62392unauthenticated-possibleagent-relevant

Apache Kylin versions 4 through 5.0.3 contain a critical OS command injection vulnerability where backend API job configuration parameters are passed unsanitized to the OS command line, allowing attackers to execute arbitrary commands on the host. With a CVSS score of 9.8, this flaw poses severe risk to any organization running affected Kylin instances, particularly those exposed to untrusted networks. Users should upgrade immediately to version 5.0.4, which resolves the issue.

sql-injectionapache-kylindata-analyticsrag-pipelineagent-relevant

A critical SQL injection vulnerability (CVE-2026-62390) affects Apache Kylin versions 4 through 5.0.3, stemming from improper neutralization of special elements in a backend API that refreshes the table catalog. Successful exploitation could allow attackers to manipulate generated SQL queries, potentially leading to unauthorized data access, modification, or full database compromise. Users should upgrade to version 5.0.4 to remediate the issue.